Levenberg–Marquardt deep neural watermarking for 3D mesh using nearest centroid salient point learning

Watermarking is one of the crucial techniques in the domain of information security, preventing the exploitation of 3D Mesh models in the era of Internet. In 3D Mesh watermark embedding, moderately perturbing the vertices is commonly required to retain them in certain pre-arranged relationship with their neighboring vertices. This paper proposes a novel watermarking authentication method, called Nearest Centroid Discrete Gaussian and Levenberg–Marquardt (NCDG–LV), for distortion detection and recovery using salient point detection. In this method, the salient points are selected using the Nearest Centroid and Discrete Gaussian Geometric (NC–DGG) salient point detection model. Map segmentation is applied to the 3D Mesh model to segment into distinct sub regions according to the selected salient points. Finally, the watermark is embedded by employing the Multi-function Barycenter into each spatially selected and segmented region. In the extraction process, the embedded 3D Mesh image is extracted from each re-segmented region by means of Levenberg–Marquardt Deep Neural Network Watermark Extraction. In the authentication stage, watermark bits are extracted by analyzing the geometry via Levenberg–Marquardt back-propagation. Based on a performance evaluation, the proposed method exhibits high imperceptibility and tolerance against attacks, such as smoothing, cropping, translation, and rotation. The experimental results further demonstrate that the proposed method is superior in terms of salient point detection time, distortion rate, true positive rate, peak signal to noise ratio, bit error rate, and root mean square error compared to the state-of-the-art methods.


Motivation
To achieve optimal stability concerning both rigid and non-rigid transformations, it's essential to perform an enhanced data embedding process that circumvents visual distortion.Analyzing the intricacy of the 3D mesh model is crucial to pinpoint areas that exhibit visual consistency and semantic importance.This approach ensures that data embedding is facilitated without compromising the visual integrity of the 3D model.Instances of compromised extraction from spatial and frequency domains by potential attackers should be prevented, with a focus on elevating the process through the integration of Artificial Intelligence models.
To attain the high embedding with less distortion a Nearest Centroid Discrete Gaussian and Levenberg Marquardt (NCDG-LV) Deep Learning method for watermark authentication of 3D models is proposed in this paper.More precisely, Salient points were extracted by employing the Nearest Centroid and Discrete Gaussian geometric measure, and 3D models were segmented using map segmentation.In addition, multi-function barycenter is used for embedding and Levenberg Marquardt Deep Neural Network Watermark Extraction is performed to concentrate specifically on the perceptual relevant regions.

Contribution
The key contributions of the proposed algorithm can be pointed out as, • The NCDG-LV deep learning method efficiently identifies salient points in 3D models using the Nearest Centroid and Discrete Gaussian geometric (NCDG) approach, leveraging Gaussian curvature to overcome data discretization challenges.• Map segmentation is achieved through a plane partitioning goal function, minimizing distortion during watermark embedding while segmenting the salient point region.• Watermark embedding is performed using a multifunction barycenter obtained through nearest centroids, ensuring effective embedding without compromising model integrity.• The proposed method employs a Levenberg-Marquardt deep neural network for watermark extraction, utiliz- ing the nonlinear characteristics of the optimized kernel to guarantee error stability and weights boundedness.
The remainder of this paper is organized as follows.Section "Literature survey", discuss various research works performed in the area of 3D model watermarking along with the pros and cons.In Section "Nearest Centroid Discrete Gaussian and Levenberg-Marquardt (NCDG-LV) Deep Learning method", the proposed Nearest Centroid Discrete Gaussian and Levenberg-Marquardt (NCDG-LV) Deep Learning method is discussed in detail.Experimental results, including comparisons with existing methods, are provided in Section "Results and Discussion".The conclusion and the future work of this paper are described in Section "Conclusion".

Literature survey
Zein et al. 1 performed Fuzzy C-Means (FCM) clustering for watermark insertion through optimized selection of vertices, minimizing perceptual distortion and enhancing robustness against attacks.This work attained Vertex Signal to Noise Ratio SNR values from 122.53 to 140.16 dB and RMSE values between 0.13 * 10 -3 and 0.27 * 10 -3 across different models and demonstrated greater resilience to cropping attacks, maintaining high resistance even at 70% cropping level.Liu et al. 2 leveraged the multiresolution adaptive parameterization of the surface (MAPS) approach to classify vertices into coarse and fine levels for watermark embedding.This selection process strategically embeds watermark information into areas that are less prone to perceptible degradation exhibiting robustness against noise, smoothing, and simplification attacks by correlation values (ρ) ranging from 0.98 to 0.49 for noise attacks, 0.91-0.48for smoothing attacks, and 0.51-0.56for simplification attacks across different models and attack parameters.
Hou et al. 3 performed on layer slicing to overcome watermark removal attacks and employed spread spectrum signal watermarking attaining correlation coefficients of 0.69 for noise attacks, 0.61 for smoothing, 0.565 for quantization, and 0.693 for 5% cropping.Liu et al. 4 introduced a novel blind watermarking technique for 3D point cloud models where vertices with larger mean curvature are embedded with a secret watermark.With 20% simplification, it achieves 0.4936 accuracy but decreases with increased noise, rotation, and cropping.Borah et al. 5 proposed a semi-fragile, blind watermarking method called, 3D-Minimum Distortion Angle Quantization Index Modulation (3D-MDAQIM) in spatial domain.The 3D mesh is traversed with a topology-oriented strategy to obtain the elite vertex units for watermark embedding.The watermark embedding is performed by www.nature.com/scientificreports/deploying dither modulation to spherical angular values of the identified vertices, causing minimum distortion, but the true positive rate is not focused on understanding the model performance.
Liang et al. 6 performed Discrete Cosine Transform (DCT) and subsequently encrypted them using the RSA algorithm to embed the watermark.The mapping of float DC coefficients to the integer domain presents challenges, as it necessitates rounding off the float part, potentially resulting in shape loss between the original and recovered 3D models.Peng et al. 7 enhanced the fidelity of reversible watermarking methods for 3D mesh models by extending 2D region nesting to n-dimensional spaces with the help of a general region nesting technique to embed semi-fragile watermarks based on vertex projection and mesh topology, facilitating authentication and integrity verification of 3D mesh models.
Delmotte et al. 8 introduced a novel blind watermarking algorithm designed specifically for 3D printed objects that employed subtle modifications to the distribution of surface norms, particularly focusing on the distance between the surface and the center of gravity.Furthermore, the algorithm subdivides the mesh into bins and disperses the data across the entire surface, effectively reducing the impact of local printing artifacts.Peng et al. 9 performed double modulation to mitigate distortion for transforming a 3D model into the spherical coordinate system through quantization modulation.Watermarks are embedded in both plaintext and encrypted domains and was able to detect malicious tampering across two domains while minimizing distortion with an average distortion of 3.749 × 10 −5 , an average maximum distortion of 0.999 × 10 −4 , an average signal-to-noise ratio (SNR) of 90.870 across 7 models and zero Bit Error Rate.Bhardwaj et al. 10 performed a novel reversible data hiding technique for 3D mesh models in the compressed domain while preserving the original mesh topology and vertex order, facilitating accurate message extraction and seamless reconstruction of the cover 3D mesh model attaining a PSNR value of 96.40 dB for an embedding rate of 6.94 bits per vertex with Hausdorff distance of 0.2358.Peng et al. 11 proposed a method using virtual polygon projection where extraction is based on vertex positions overcomming tampering attack.With double modulation strategy, the average and maximum distortion are decreased by 0.0411 and 0.1608, and the average SNR is increased by 2.5649 compared with IQIM (Fei Peng et al. 12 ), respectively.
Lee et al. 13 performed zero-watermarking method that includes coordinate correction, spatial partition, gene feature extraction, and genotype detection.The statistical examination of distortion attacks on a zero-watermarking method demonstrated robust resistance to noise addition (1.00 ratio), cropping (correlation > 0.88), and subdivision attacks (correlation > 0.94 in the midpoint scheme).Peng et al. 14 performed spherical crown volume division to minimize embedding distortion and topological transformations during watermark generation.By grouping the converted spherical coordinates based on their one-ring neighborhood, tampering localization accuracy is improved.Yang et al. 15 analyzed a steganalysis algorithm to enhance the 3D watermarking techniques developed by Cho et al. for detecting the embedded watermark through bimodal distribution of histogram bins' means/variances based on radial coordinates.Rather than integrating each watermark bit within a continuous statistical feature this model embedded within a discrete statistical measure, particularly focusing on the variance between two adjacent bins.The steganalysis algorithm achieves 98.65% accuracy in estimating the number of bins in the variance-based method and demonstrates robustness against noise addition, smoothing, quantization, subdivision, and simplification, maintaining high correlation coefficients even after significant attacks.
Jiang et al. 16 performed bit-stream encryption to embed the watermark using data-hiding key in least-significant bits.Leveraging spatial correlation within natural mesh models, ensured the good recovery of the original mesh achieving an embedding rate of 0.7 bits per vector.On the Princeton Shape Retrieval dataset, the average error rate stands at 4.2%, while with the Stanford 3D Scanning Repository, error rates range between 9.7 and 11.4%.Nassima et al. 17 derived salient points using a 3D salient point detector based on the Auto Diffusion Function, followed by segmentation of the 3D model into regions anchored to these salient points.The watermark is then inserted into each region using the embedding technique of Cho et al.By employing geodesic Voronoi segmentation, the surface is divided into cells associated with feature points, allowing for precise watermark embedding and extraction and able to achieve Haussdorff distance (HD) values ranging from 0.33 to 10.7 × 10 -3 and minimal roughness.
Niu et al. 18 discusses the use of Laplace-Beltrami eigen functions that are invariant to rigid transformations to extract salient points representing distinctive regions computed based on specific criteria, including clustering and geodesic distance computations.Feng et al. 19 presented a novel mesh visual quality metric that integrated saliency considerations to estimate local distortions in the mesh.Li et al. 20 performed multiresolution 3D wavelet analysis, Laplacian smoothing and normalization and Wavelet Coefficient for watermarks embedding and extraction.Zhang et al. 21enhanced Reversible Data Hiding approach using prediction-error expansion and embedded the watermark in adjacent neighbors generating a ring pattern for easy prediction vertex.Data bits are embedded reversibly into 3D mesh models via operations like expansion, shifting, and LSB replacement with smoothness sorting and a twice-layered strategy and achieved a good SNR of 45 dB with 0.7 bits per vertex embedded.
The need for robust and secure methods to protect 3D models has led to an increase in the significance of research in the area of deep learning approaches and 3D mesh watermarking in recent years.Deep learning methods promise great embedding capacity, robustness against attacks, and imperceptibility of embedded watermarks, providing distinct advantages in capturing intricate features and learning complicated mappings within 3D meshes.Several obstacles must be overcome by researchers as they work in this field, including a lack of labeled training data, overfitting, interpretability issues, adversarial attacks, and computational complexity.Notwithstanding these obstacles, there is a lot of potential for revolutionizing digital material security and authentication through the investigation of deep learning techniques for 3D mesh watermarking.
Zhu et al. 22 employs a Graph Attention Network (GAT) to extract local features from vertex relations, providing robustness even after mesh simplification.Additionally, an attack layer perturbs the watermarked vertices to augment robustness against cropping, noise, rotation, translation, and scaling attacks.Wang et al. 23 introduces the deep 3D mesh watermarking network, where the curvature consistency loss function is created to limit the www.nature.com/scientificreports/local geometry smoothness of watermarked meshes in order to maintain the visual quality of 3D meshes.The architecture includes embedding, extracting sub-networks, and attack layers, employing topology-agnostic graph convolutions for flexible mesh handling.The approach tried to ensure robustness with adaptive attack layers and maintains visual quality via a curvature consistency loss for smooth watermarked mesh geometry.Abouelaziz et al. 24 computed visual saliency using a method based on mean curvature and Gaussian filtering to select relevant patches from rendered 2D projections of the 3D model.Then a simple local contrast normalization is applied to address illumination and contrast variations.For feature learning and quality score estimation, three pre-trained CNN models (AlexNet, VGG, and ResNet) are fine-tuned, and their extracted features are combined using Compact Multi-linear Pooling (CMP) to interact multiplicatively.The combined features are fed into fully connected layers followed by a regression layer for quality score prediction.This approach showcases the integration of deep learning and saliency analysis for efficient and accurate quality assessment of 3D meshes.
The advancements in 3D mesh watermarking techniques have seen significant progress, with various methods addressing different aspects of robustness, imperceptibility, and resilience against attacks.From employing clustering algorithms like Fuzzy C-Means for vertex selection to leveraging multiresolution adaptive parameterization and spread spectrum signals for watermark embedding, researchers have explored diverse approaches to enhance the security and authentication of 3D models.Techniques such as deep learning-based approaches, reversible data hiding, and graph attention networks have shown promise in overcoming challenges like overfitting, interpretability issues, and adversarial attacks.Despite obstacles such as a lack of labeled data and computational complexity, the field of 3D mesh watermarking is poised for further development, especially with the integration of deep learning methodologies, saliency analysis, and robust watermark embedding strategies.These advancements hold the potential to revolutionize digital material security and authentication, paving the way for more secure and reliable methods in the realm of 3D model protection.

Nearest Centroid Discrete Gaussian and Levenberg-Marquardt (NCDG-LV) Deep Learning method
Structure of the proposed method for 3D mesh authentication is demonstrated in Fig. 1.Initially, the Nearest Centroid and Discrete Gaussian geometric (NC-DGG) Salient Point Detection model is used to detect the optimally and computationally efficient salient points.Second, with the detected salient points, 3D Mesh model is segmented into regions using map segmentation.Third, the watermark is inserted into each region using the multi-function barycenter-based Watermarking Embedding model.Finally, the watermark is extracted by employing the Levenberg-Marquardt deep neural network watermark extraction model for achieving good imperceptibility and robustness against attacks.

3D mesh model representation
A 3D mesh has structural construct of a 3D model consisting of polygons.Triangle mesh has type of polygon mesh.It includes a set of triangles in three dimensions that are linked with edges or vertices.3D mesh model has denoted as three-dimensional object that includes points (i.e., vertices), lines (i.e., edges), and faces (i.e., surfaces).www.nature.com/scientificreports/These elements are employed to refer the shape of the modeled 3D object.The 3D mesh model is comprised of a set of vertices ' V ' in Cartesian coordinates and a set of edges ' E ' represented as ' G = (V , E) ' .Let us consider that ' V i ' corresponds to the vertex indexed by ' i ' and is designated by its corresponding 3D coordinates ' The vertices group that is adjacent to a neighborhood vertex ' V i ' is referred to as ' 1 − ring ' of the vertex, and the number of vertices that is adjacent to neighborhood vertex ' V i ' in the ' 1 − ring'is referred to as the degree of the vertex ' V i ' .In a similar manner, the ' k − thring ' neighborhood vertices around vertex ' V i ' can be obtained by means of the K-Nearest Centroid Discrete Gaussian geometric measure.Some of the 3D mesh models used in the proposed work is shown in Fig. 2.

Nearest centroid & discrete Gaussian geometric (NC-DGG) salient point detection
The salient characteristics of 3D mesh models are distinctiveness, resilience, invariance, repetition, localization, semantic meaning, efficiency, and scalability.These geometric properties are essential and has significant importance in several applications, such as shape analysis, recognition, and embedding.These points typically include regions with significant curvature, points of utmost magnitude, angular points, and locations along the boundary.Identifying them is crucial for acquiring complex features, essential structural elements, and unique geometric properties to embed secrets in the mesh model.Embedding approaches, utilizing salient points, can efficiently encode and depict geometric information while exhibiting resilience against noise, distortion, and geometric attacks.
Figure 3 shows the structure of the Nearest Centroid and Discrete Gaussian geometric (NC-DGG) salient point detection model.The 3D mesh model salient point detection method, is analyzed using the 3D models obtained from Princeton Shape Benchmark to identify prominent features from the geometric attributes and its spatial relationships.Initially, the method employed the nearest centroid technique to identify central points within the mesh, serving as potential candidates for salient points.Leveraging an Optimal 3D salient point detection function, the method assesses various geometric properties and vertex densities to discern salient features from background elements.By applying a Discrete Gaussian Kernel function, local distributions of vertex densities are computed, illuminating regions of higher significance.Subsequently, a 3D salient point counter function  www.nature.com/scientificreports/quantifies the saliency of each candidate point based on its proximity to dense vertex clusters and its contribution to shape distinctiveness.The evaluation extends to analyzing the Euclidean distance of neighborhood vertices, which aids in discerning salient features amid the mesh's structural complexity.By scrutinizing the distribution and spatial relationships of salient points, including the alignment of right-angled lines connecting neighboring vertices, the method systematically identifies and characterizes salient features within the 3D mesh model, enabling effective feature extraction and shape analysis for diverse computational applications.
As shown in Fig. 3, for every vertex v on a 3D mesh model, n denotes the normalized vector.Only one right- angled plane exists for this vertex v , which is estimated as: where (p, q, r) denotes the coordinates of vertex ' v ' and p v , q v , r v represents the vertex normal.The average distance of the kth ring neighborhood vertices around vertex ' V i ' is formulated as: where ' p ij , q ij , r ij ' corresponds to the ' j − th ' coordinate of the 3D mesh model in ' V i (k) ' for ' N ' different sam- ples.Consider that ' M p, q, r ' denotes the 3D mesh model acquired from 25 .New 3D mesh models M α p, q, r are generated around vertices in the original mesh model.These new models are created based on the neighborhood vertices surrounding the target vertex and are related to the original mesh through the application of a discrete Gaussian kernel function.The purpose of employing this function is to determine the salient scale, providing insight into the significant geometric features within the local neighborhood of the target vertex v.
where ' α = (ε, 2ε, 3ε, . . ..nε) ' corresponds to the standard deviation of the respective 3D Discrete Gaussian Kernel filter ' DG ' and ' ε ' refers to the distance of the main slant in the nearest neighbor vertex of the model.Based on the distance geometric measure, a 3D salient point counter function is defined that authorizes us to extract non-cognitively significant salient points from 3D mesh models.For any vertex ' V i ' in a 3D mesh model, we utilize the counter function as follows: where ' β ' corresponds to the distance geometric measure of vertex ' v ' in scale ' s = 1, 2, 3, . . .n ' , which is modeled based on the minimum distance function ' Min Dis ′ s ' and maximum distance function ' Max Dis ′ s ' in which ' Dis ′ ' represents the summation.With the obtained 3D salient point counter function for every vertex ' v ' , the value of the counter function is compared for every vertex ' v ' in its Nearest Centroid rings.If the value of ' β ' is greater than all the values ' β ' in its Nearest Centroid rings, the vertex ' v ' is said to be the selected optimal salient point; otherwise, the vertex ' v ' is not a salient point.The pseudo code representation of Nearest Centroid and Discrete Gaussian salient point detection is given below. (1) (3) M α p, q, r = M p, q, r * DG p, q, r, α

Map segmentation
After acquiring the salient points, the 3D mesh models are further segmented into distinct sub regions Green plane, and Blue plane with the plane partitioning map function.The map functions are separated geographic regions in the model, associated to the salient points, and constructed by means of a plane partitioning goal function.The planes are then divided into ' n ' sub regions SR = SR 1 , SR 2 , SR 3 , . . .., SR n in such a manner that each region consists of approximately a ratio of ' 1 n ' green partitions and ' 1 n ' blue partitions.For each subregion SR i , Eq. ( 7) computes the sum of the intersections of the green plane 'G' (Plane G ) and the blue plane 'B' (Plane R ).The maximum value across these intersections represents the evolved regions resulting from the segmentation process.

Multi-function barycenter and Levenberg Marquardt Deep Learning Model
Following the segmentation process, the multi-function barycenter is utilized to perform watermarking embedding.Figure 4 shows the structure of the multi-function barycenter-based watermarking embedding model.
The watermark ' W = (W 1 , W 2 , W 3 , . . ., W n ) ' is embedded by persuading each ' W i ' with a small shift in a sub- set of ' V ' .A vertex v is noted as ' V p v , q v , r v ' or ' V p v ′, q v ′, r v ′ ' before or after embedding, respectively.Calculate displacement factor l used to adjust the positions of the barycenters within the mesh as shown in Eq. ( 8).Higher values of l could lead to larger displacements, resulting in more significant changes in the mesh geometry.For each being a salient point ' v ' , its ' p v ' value is divided by the parameter ' G w ' that controls granularity or scale of the embedding to nearest integer.By controlling the scale of the adjustments made to ' p v ' as shown in Eq. ( 8), the watermark can be embedded in a way that is resilient to common attacks or transformations applied to the mesh model, such as scaling, rotation, or translation, ensures consistency across the embedding process, allowing for reproducible results and predictable behavior when embedding the watermark into different regions of the mesh or across multiple meshes.Next, for each salient point its ' q v ' and ' r v ' barycenters are measured by obtaining the mean of the coordinates of its Nearest Centroids as: where ' NC(v) ' refers to the set of ' v′s ' nearest centroid value; and ' |NC(v)| ' corresponds to the size of ' NC(v) ' .Finally, the watermark ' W i ' and hash value ' H(W i ) ' are embedded in ' M E v 'formulated as given below: Finally, S denotes the embedded watermark, Cryptography hash function is used for calculating H(W i ) , and the length of H(W i ) is 128 bit.The embedding perturbs ' M E v ' toward the original value ' p v , q v , r v ' with a small shift ' Sh j ' , which is always less than ' j = (2, 3)' .

Levenberg-Marquardt deep neural network watermark extraction
In the watermark extraction stage, ' G w ' and ' H ' serve as the pivotal elements for detecting any malicious pat- terns.In the proposed work, with the objective of improving the precision and recall involved in the watermark embedding and extraction process, a Levenberg-Marquardt deep neural network watermark extraction model is used.Figure 5 displays the structure of Levenberg-Marquardt deep neural network watermark extraction model.
Figure 6 demonstrates the structure of Levenberg-Marquardt deep neural network to perform watermark extraction.It includes an input layer, hidden layer, and output layer.In the input layer, ' V i ' is a dynamic vertex that passes over the entire 3D Mesh model, initiating from ' V i ' , to inspect the model.In the hidden layer, the corresponding ' q v ' and ' r v ' barycenters of each salient point and segmented portions are estimated using Eqs.( 9) and (10), respectively, and then used to extract the watermarks as follows: For each vertex ' V i ' , the weights associating the input-hidden and hidden-output layers are updated according to the desired output, and the process is iterated until the convergence.Subsequently, the network trained model is utilized for classification of the test set.This process is performed two times, one for the top half segmented regions ' TH ' and the second for the bottom half ' BH ' segmented regions.This is formulated in Eqs. ( 14) and ( 15): Finally, the output layer constitutes the extraction result, i.e., distorted regions or non-distorted regions.To speed up the watermark extraction process and minimize the memory, the Levenberg-Marquardt

Estimation of salient point detection time
The detection of salient point is an essential parameter since it reveals the portions to be watermarked in a precise manner during watermark embedding.The salient point detection time is measured as follows: The salient point detection time ' SPD t ' is measured in milliseconds (ms) for each 3D mesh models used in the watermarking process ' M i ' and the time consumed in detecting the actual salient point ' Time[β] ' .Herein, salient point detection is performed on various 3D mesh models, and the resultant results are shown in Fig. 7.The estimation was performed for the models with size lower to higher showing the time taken for small size models are less and inverse for the other case.
Due to the different sizes of 3D mesh models, the salient point detection time varied.The salient point detection time complexity is significantly smaller for a single 3D mesh model and higher for large number of models.For the first simulation run, the salient point detection time obtained by the proposed NCDG-LV method, Laplace-Beltrami 3D 18 , 3D-MDAQIM 5 , and Deep 3D mesh watermarking network 23 was determined to be 7.75, 9.25, 10.25 and 8.15, respectively.The better salient point detection time of NCDG-LV, which was 30%, 48% and 18% faster than the three other respective methods, can be attributed to the Nearest Centroid function employed via the Discrete Gaussian Kernel function.

Embedding and extraction
Watermarks are embedded into the segmented regions obtained by plane partitioning mapping through the extracted salient points.The watermark which is the thumbnail view of the 3D model is embedded into the resulting region through multi-function barycenter and is shown in Fig. 8.The resulted 3D model after embedding shows some visible visual distortions depending on the size of the original 3D model and the watermark.The watermarked model is trained and tested to extract the watermarks from the salient point through Levenberg-Marquardt deep neural network.

Performance evaluation of centroid discrete Gaussian and Levenberg-Marquardt
To evaluate the performance of the proposed method, four objective parameters, including watermark extraction against different attacks, spatial detection time, distortion rate, true positive rate, and PSNR are considered.

Peak Signal to Noise Ratio
The peak signal-to-noise ratio (PSNR) is evaluated to evaluate the imperceptibility based on the mean square error using the Eq. ( 17) and the results obtained from different methods are shown in Table 1: where MAX is the maximum possible value coordinate.
Root Mean square Error (RMSE) given in Eq. ( 18) identifies the geometrical distortion between two meshes, where v, ′ v refers to the vertices of original mesh M and deformed meshes surface M ′ , and N refers to number of vertices in the mesh model.
Table 1 provides a comparative analysis of the PSNR of the four different methods.For fair comparison, the above analysis was conducted using 10 3D mesh models, namely rabbit, vase, bee, face, horse, table, bird, spider, ant, and dog models.In PSNR with attacks, 14.7 KB image size is considered to evaluate the experiments.The average PSNR of proposed NCDG-LV for 10 models is 55.02, whereas the PSNR of existing 5,18,23 is 52.52, and 50.38, and 53.35 respectively.

Bit Error Rate (BER)
Bit error rate measures the accuracy of watermark extraction, representing the ratio of incorrectly decoded bits to the total number of bits in the watermark as given in Eq. (19).Achieving a lower bit error rate with better embedding capacity plays a major role in watermarking scheme and the results obtained from different methods are shown in Table 2: where n b is the number of bits embedded, and δ is the Kronecker delta function.1 and 2, we can observe the better PSNR and bit error rate as compared to the other state of the art methods after embedding the watermark information in 3D mesh models.

Distortion rate between the host and watermarked model
The robustness of the proposed watermarking method is analyzed for the distortions created due the embedded watermark.To evaluate the robustness of the proposed method, the distortion rate 'DR' was calculated as follows (Eq.20): Distortion rate refers to the amount that a watermark is not detected in the attacked 3D mesh model and is based on the number of detected false negatives ' #FN[D] ' and the total number of detections ' D ' .In other words, a smaller distortion rate value is desirable.Herein, the Levenberg-Marquardt Deep Learning Extraction algorithm is evaluated on fifty distinct 3D mesh models, and the resultant results are shown in Fig. 9. Despite the very high number of 3D mesh models for the simulation, the proposed method achieved a smaller distortion rate compared to Laplace-Beltrami 3D 18 , 3D-MDAQIM 5 , and Deep 3D mesh watermarking network 23 .
Figure 9 presents the graphical representation of distortion rate using the three approaches for 50-500 different 3D mesh models.The 3D Mesh distortion rate refers to the degradation process involved in the watermarked 3D mesh model due to secret embedding.From the results, it can be inferred that the distortion rate obtained by the three different methods is directly proportional to the number of 3D mesh models provided as input.In other words, by increasing the number and size of 3D mesh models, a significant amount of distortion is also said to occur.As the rate of embedding increases, a small amount of visual degradation is caused, therefore resulting in the distortion.For 50 3D mesh models, the distortion rate of NCDG-LV, Laplace-Beltrami 3D 18 , 3D-MDAQIM 5 , and Deep 3D mesh watermarking network 23 was found to be 1.2, 1.6, 2 and 1.4 respectively.The reason behind the improvement of the proposed method can be owed to the incorporation of multi-function barycenter using Levenberg--Marquardt, which separates the top half and bottom half of the segmented subregions and subsequently reduces the distortion.Table 1.PSNR of NCDG-LV method, Laplace-Beltrami 3D 18 , and 3D-MDAQIM 5 , Deep 3D mesh 23

Performance analysis of true positive rate
The true positive rate, or sensitivity, refers to the percentage of testing models that have been properly authenticated with a watermark.The true positive rate ' TPR ' is measured using Eq. ( 21): True positive rate is based on the true positives ' TP ' (authenticated with the 3D mesh watermark) and false negatives ' FN ' (not authenticated with 3D mesh watermark but is assumed to be authenticated).To demonstrate the watermark authentication efficiency of the proposed NCDG-LV, the obtained true positive rate was compared to those of three other methods, as seen in Fig. 10. Figure 10 presents the true positive rate results of the three methods in the watermark authentication process.As shown in the graphical results, the true positive rate of three different methods gets increased or decreased while increasing or decreasing the input from 50 and 500.This is because the true and false watermark authentication depends on the detection of salient points being detected and on the map segmentation performed for the detected points.The obtained true positive rate was compared to those of three other methods.From the results show that the true positive rate was found to be 90%, 88%, 84% and 89% using the four methods, respectively.The better performance is attained due to the enhancements generated by the multi-function barycenter and Levenberg-Marquardt Deep Learning Extraction functions.

Watermark extraction against different attacks
To prove the robustness of the proposed approach, the watermarked model is tested with smoothing, Gaussian noise, cropping, and translation attacks on four different methods, including NCDG-LV, Laplace-Beltrami 3D 18 , and 3D-MDAQIM 5 , and Deep 3D mesh watermarking network 23 .www.nature.com/scientificreports/

Smoothing attack
In more complex models, you might want to retain some degree of sharpness in certain areas while smoothing others.A surface smoothing algorithm is applied to test the robustness of the proposed method over 5, 10 and 15 iterations and compared with other state of the art methods in terms of PSNR and shown in Fig. 11.

Gaussian noise attack
Gaussian noise of 1%, 2%, and 5% is added to the models to test the robustness against noise attacks and the amount of distortion after adding noise is shown in Fig. 12 as a value of PSNR and the same is compared against the other state of the methods and shown in Table 4.

Cropping attack
The 3D mesh models are cropped 3%, 6%, and 9% to test the robustness against cropping attacks and the amount of distortion after cropping is shown in Fig. 13 as a value of PSNR.
The experimental results show that the proposed method exhibits good robustness against attacks mentioned above, and the segmented watermarking provides better visual quality on an image compared with Laplace-Beltrami 3D 18 , 3D-MDAQIM 5 , and Deep 3D mesh watermarking network 23 .The Nearest Centroid Discrete Gaussian and Levenberg-Marquardt method displays high imperceptibility and robustness.The watermarked images were corrupted by Gaussian noise of 1% variance.For the cropping attack, a small portion of the watermarked image was removed.NCDG-LV model includes the following process: Salient point detection using Nearest Centroid and Discrete Gaussian geometric (NC-DGG) is considered as the baseline of the proposed model.This selected point regions are further segmented using Map Segmentation (MS).This region is embedded with secret watermark using multi-function Barycenter to generate the watermarked 3D model (MF_B).The watermarks are extracted

Conclusion
An effective Nearest Centroid Discrete Gaussian and Levenberg-Marquardt watermarking method for 3D mesh authentication is presented.In this technique, a novel geometric Nearest Centroid Discrete Gaussian is used to identify the salient points, and bits are embedded into the segmented portion of a 3D mesh using multi-function barycenter embedding.This, in turn, helps to reduce the distortion rate.In addition, Levenberg-Marquardt extraction is applied to extract the watermarked image.The experimental results demonstrate the proposed method achieves good imperceptibility and robustness against attacks and is comparatively better to other stateof-the-art methods in terms of salient point detection time, distortion rate, and true positive rate.
In future we would like to explore watermarking techniques that dynamically adapt the embedding strength of the watermark in accordance with the sensitivity of the mesh model.And, explore new strategies for watermark placement within 3D mesh models that are intelligently coordinated with the inherent semantic features of the content to provide effective protection with the least amount distortion.

Figure 2 .
Figure 2. Some of the 3d mesh models used in the proposed method.

Figure 3 .
Figure 3. Structure of Nearest Centroid and Discrete Gaussian geometric (NC-DGG) Salient Point Detection model.

Figure 7 .
Figure 7. Salient point detection time of first 10 models.

Figure 11 .
Figure 11.Average PSNR of extracted watermark after smoothing attack over 50 mesh models.
on a set of 10 distinct 3D mesh model.

Table 3 .
Bit error rate of three methods with smoothing attacks.www.nature.com/scientificreports/metrics employed to demonstrate the performance of the proposed NCDG-LV 3D model watermarking are PSNR, bit error rate, distortion rate and TPR.The performance of the proposed method is evaluated based on various attacks like smoothing attack, Gaussian noise attack and cropping attack.

Table 4 .
26NR of NCDG-LV method, Laplace-Beltrami 3D18, and 3D-MDAQIM5, Deep 3D mesh23on a set of 10 distinct 3D mesh models with 1%, 2%, and 5% noise.PSNR for the original watermark and extracted watermark after cropping the model for 3%, 6%, and 9%.using the Levenberg-Marquardt deep neural network (LM_DN).The ablation study is performed with other methods like selection of random vertices instead of salient points, clustering in the process of map segmentation, LSB embedding26instead of barycentric method to show the improvements attained with respect to PSNR and Bit Error rate.